Discourse

Discourse

238 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Veröffentlicht 19.03.2026 21:49:33
  • Zuletzt bearbeitet 23.03.2026 20:11:17

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, users who do not belong to the allowed policy creation groups can create functional policy acceptance widgets in posts under the right condi...

  • EPSS 0.01%
  • Veröffentlicht 19.03.2026 21:45:13
  • Zuletzt bearbeitet 23.03.2026 20:16:43

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a security flaw in the discourse-policy plugin which allowed a user with policy creation permission to gain membership access to any pri...

  • EPSS 0.02%
  • Veröffentlicht 19.03.2026 21:42:36
  • Zuletzt bearbeitet 23.03.2026 20:17:51

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a restriction bypass allows restricted post action counts to be disclosed to non-privileged users through a carefully crafted request. Versi...

  • EPSS 0.03%
  • Veröffentlicht 19.03.2026 21:33:38
  • Zuletzt bearbeitet 23.03.2026 20:18:31

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a vulnerability in an API endpoint that discloses private topic metadata of admin users to moderator users even if the moderators do not...

  • EPSS 0.04%
  • Veröffentlicht 19.03.2026 21:17:43
  • Zuletzt bearbeitet 25.03.2026 21:04:13

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a lack of visibility checks with a user action API endpoint that results in disclosure of the title and post excerpt to unauthorized use...

  • EPSS 0.03%
  • Veröffentlicht 19.03.2026 21:17:09
  • Zuletzt bearbeitet 25.03.2026 00:58:33

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a cross-site scripting vulnerability that arises because the system trusts the raw output from an AI Large Language Model (LLM) and rend...

  • EPSS 0.01%
  • Veröffentlicht 19.03.2026 20:52:17
  • Zuletzt bearbeitet 25.03.2026 00:59:29

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the onebox method in the SharedAiConversation model renders the conversation title directly into HTML without proper sanitization. Versions ...

  • EPSS 0.03%
  • Veröffentlicht 19.03.2026 20:47:54
  • Zuletzt bearbeitet 25.03.2026 01:00:41

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a type coercion issue in a post actions API endpoint allowed non-staff users to issue warnings to other users. Warnings are a staff-only mod...

  • EPSS 0.04%
  • Veröffentlicht 19.03.2026 20:39:28
  • Zuletzt bearbeitet 25.03.2026 01:01:56

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, requesting /posts/:id.json?version=X bypassed authorization checks on post revisions. The display_post method called post.revert_to directly...

  • EPSS 0.03%
  • Veröffentlicht 19.03.2026 20:29:22
  • Zuletzt bearbeitet 25.03.2026 01:06:00

Discourse is an open source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1 and 2026.1.2, insufficient cleanup in the default Codepen allowed iframes value allows an attacker to trick a user into changing the URL of the main page....